[ALSA-2026:59496] Important: nginx:1.26 security update
Type:
security
Severity:
important
Release date:
2026-09-01
Description:
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): * nginx: NGINX: Heap buffer over-read allows memory modification or denial of service (CVE-2026-56434) * nginx: NGINX: Memory disclosure and denial of service in ngx_http_slice_module (CVE-2026-60005) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 nginx-mod-http-perl-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 248546f2f14677a7f0568c1d8d5dc0b77e7b6957e9cbb1221b983a0ece5fd811
aarch64 nginx-mod-http-xslt-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 32ee8e2ac2db768011531163b5d61710b246d791a7fcc0535e0a389fbcfd3339
aarch64 nginx-mod-http-image-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 7945a858c11fd9f26f9f5346785a5f927084748dcad0215133e83e8f18382478
aarch64 nginx-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 8181be3271d24248ebeddf66d8f0e262e29114496b3817b1846b4c86e70a60d0
aarch64 nginx-core-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 887a740d9857107106daf425e0107f7b79b6ce4c54ae3ae02cbdd0346adf4b62
aarch64 nginx-mod-stream-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 8aa84825b92ebd03563e2f1a4536b394660d48b4ed318e8b3aa80b42c123bae9
aarch64 nginx-mod-mail-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm 958ce5a2793826a5e742c229985ead4812f19d792684f75256deba34cb929ae4
aarch64 nginx-mod-devel-1.26.3-9.module_el9.8.0+300+0781a894.3.aarch64.rpm d4e2af88ef0fb84879d503447178a23da4f31618fd14d55b4878f40775ca5cae
noarch nginx-all-modules-1.26.3-9.module_el9.8.0+300+0781a894.3.noarch.rpm 61459217a8cef686f96e73cbc4848db3c0558ed07576219c4f4bf4c499b65624
noarch nginx-filesystem-1.26.3-9.module_el9.8.0+300+0781a894.3.noarch.rpm 6df3a09d14e1aa4f86305f9f4386e058a6def79b3c97e635890054f2a4032638
ppc64le nginx-mod-stream-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm 3d57bc9eeb396dbc3e677fff255dae87fbd37216f4cf958e45e2b814658cbceb
ppc64le nginx-mod-http-xslt-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm 71972e7b2497a38bcbe065302e1745182a4bd696b467dbc0968db6033f8d3df0
ppc64le nginx-mod-http-image-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm 76d288814c966f8dd1e29908f72e35c43b6d3d08304de191bc449ee247fa5363
ppc64le nginx-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm 832489fd39f2cb8d0bd4a2749a0ef4e0422ed917686cf2efa2a576567b601de2
ppc64le nginx-mod-devel-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm 9cced75285c366ba34219ab579ea29410b5bdacda2e1d734690f00cd4493c31a
ppc64le nginx-mod-mail-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm a5e325adde5e396ae56a6c4f43f3c968e30462a2b583a9a9122a63a83c379e93
ppc64le nginx-core-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm ad16e64404292e5e9ac608b2aaf7394b7623b4df557b24546a650ce04fca1d8c
ppc64le nginx-mod-http-perl-1.26.3-9.module_el9.8.0+300+0781a894.3.ppc64le.rpm e53b620afb2d60b78186d21dfb4ceaad06639080c31b6900648c48e953ec9788
s390x nginx-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm 4f5fe41211250a190da1de82edc4ec81abeb1ae84ad4621436489b6300148da1
s390x nginx-mod-devel-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm 5af4674b63f7b2eca4cb8350a4a716e23a5de332c1b29f1800823261deb66e58
s390x nginx-mod-http-xslt-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm 6bf732cf1fc0735d82ad642322f0220176e325cfcab7bd2c204f31d09db98f43
s390x nginx-mod-mail-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm cf1fb260ef0001080ced8a471f86fb4a6a575d2f774a87089c752804757c1903
s390x nginx-core-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm d6c2a345181bf2e8fb93ca16c66e632797b1820480dedcac8605538576e5f5cd
s390x nginx-mod-stream-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm dbe28a32c5c0e083c6ca7593d8d15d9af742a68b885ad06fb127b534627b4f7a
s390x nginx-mod-http-perl-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm e03d4068cf8b2cd861345fdb49647316ea34b19c24c14a0acd269a0f2af45da8
s390x nginx-mod-http-image-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.s390x.rpm efcd37f3aae1b99408b6167861622500e515a526f1ea258bc2d8a7c4edb5e6c1
x86_64 nginx-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 4a31735cc60cca273915a979b67d94e388a3ca0ddeac377e9b31ca4293ff4ab8
x86_64 nginx-mod-devel-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 610a3218314b6d88c9eb12806dad13b80d83c77244604b11dcd9479c8f979a18
x86_64 nginx-mod-http-image-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 755da0f2067c6efb986dd5d40b8f371906c8b3b76d58849d6fe19f460589a24e
x86_64 nginx-mod-stream-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 93e6f743e1ea14b88da9ef59715b7b82e8b4712b8b8f8745ce5f98a4c9bf395a
x86_64 nginx-mod-http-perl-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 9c89e38ffe69c76fce86290c1f7acff74815cc8646d540bdaa00bae2f677cf21
x86_64 nginx-core-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm 9ec8e0eb44015038b914b4173b6106233b6b6da91e2a6b7d17d4dcd1e41aa260
x86_64 nginx-mod-http-xslt-filter-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm b217bf8ad2a55780a08e35777a8131703f786f6e87fe574eb2c06b1054d62244
x86_64 nginx-mod-mail-1.26.3-9.module_el9.8.0+300+0781a894.3.x86_64.rpm f9ce1bcccf7fcbfe5ecf8dee97c47e13af5a6fad63332607d9662272aaa34bc9
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.